BigHugger
sk Skill · PentesterFlow

jwt

JWT attack playbook — algorithm confusion (alg=none, HS/RS confusion), kid path traversal/SQLi, jku/x5u SSRF, weak HS256 cracking, and embedded JWK trickery. Use when the target uses JWTs for auth (header.payload.signature).

installs 8w
0
30-day movement
starts with the next reading
Related entries
2
Connections
4
pythonbashTypeScript
Host repository
PentesterFlow/agent
Allowed tools
http, shell, read_payloads, file_write
Host stars
1,360
Host language
TypeScript